1. Scope

This policy applies to grenval.info, Grenval Health Ltd and communications sent from the platform. It explains what information may be received, why it is used and the choices available to visitors. The policy is intended for readers in the United Kingdom. It was updated on 24 September 2026. It covers every page reachable from the main navigation, including the six article pages on men's heart and cardiovascular wellbeing, the newsletter sign-up form on the homepage and the contact form described on the contact page. It does not cover the practices of external websites that a reader may reach by following a link from an article, since those sites operate under their own privacy notices. Where Grenval Health Ltd acts as the controller of personal information described in this policy, decisions about why and how that information is processed are made by the editorial and operations team based at the registered address given below.

  • a) The policy applies equally to information submitted through a desktop browser or a mobile device.
  • b) Where an embedded third-party service, such as a map, is used, that provider's own privacy notice governs the information it collects directly.
  • c) A printed or archived copy of an earlier version of this policy can be requested using the contact details in Section 11.

2. Information received

When a reader submits a newsletter form, Grenval may receive an email address and the information voluntarily entered. Server logs can contain an IP address, browser type, requested page and time of access. Contact messages may include a name, email address and the contents of the enquiry. No special category health information is knowingly requested through any form on this website, and readers are asked not to include sensitive personal details, such as a specific assessment or supplement routine history, in a contact message. Where a reader nonetheless includes such detail voluntarily, it is treated with the same confidentiality as other correspondence and is not used to build a profile or to personalise advertising. Server log data is collected automatically by the hosting infrastructure as a normal part of running a website securely, rather than through any cookie or tracking pixel placed in the browser.

  • a) Newsletter data: email address and any optional name field completed at sign-up.
  • b) Contact form data: name, email address, subject and message content submitted voluntarily.
  • c) Technical log data: IP address, browser and device type, referring page and timestamp, collected for security and reliability purposes.

3. Lawful basis

Newsletter processing is based on consent. Replying to an enquiry relies on steps requested by the sender and legitimate interests in administering correspondence. Security logs are retained under legitimate interests in keeping the website reliable and protecting its infrastructure. Consent for the newsletter is obtained through a clear opt-in action at the point of sign-up, and no reader is added to the mailing list by default or as a condition of using another part of the website. Where legitimate interests are relied upon, Grenval has considered whether the processing is proportionate and has concluded that maintaining a functioning, secure website and responding to enquiries sent voluntarily does not override a reader's own interests or fundamental rights under UK GDPR. A reader can ask for further detail about the balancing test applied to any specific legitimate interest by writing to the address in Section 11.

  • a) Newsletter sign-up: Article 6(1)(a) UK GDPR, consent, withdrawable at any time.
  • b) Enquiry handling: Article 6(1)(b) and 6(1)(f), contractual necessity and legitimate interests in correspondence.
  • c) Security logging: Article 6(1)(f), legitimate interests in protecting the website against misuse.

4. Retention

Newsletter details remain until a person unsubscribes or the list is reviewed after 24 months of inactivity. Contact correspondence is normally retained for 12 months after the last meaningful exchange. Security logs are normally retained for 90 days, unless a longer period is needed to investigate abuse. These periods reflect a proportionate balance between operational need and data minimisation, and each category is reviewed periodically to confirm the stated period remains appropriate. An example of an inactivity review is a newsletter address that has not opened or clicked a single issue in 24 months, which is flagged for removal from the active list during a routine data hygiene exercise. An example of an extended retention edge case is a security log connected to a suspected attempt at unauthorised access, which may be retained beyond 90 days for the specific purpose of investigating that incident and, where relevant, reporting it to a hosting provider or, in a serious case, to Action Fraud or the police.

  • a) Newsletter list: retained while active, reviewed after 24 months of no engagement, removed or re-confirmed thereafter.
  • b) Contact correspondence: retained for 12 months after the last reply, then deleted or anonymised.
  • c) Security and access logs: retained for 90 days as standard, extended only where an active investigation requires it.

5. Rights

Under UK GDPR, a person may request access, correction, erasure, restriction, portability or objection where applicable. Consent can be withdrawn at any time by using the unsubscribe link or contacting [email protected]. Requests are answered within one month, subject to identity checks and lawful exceptions. In practice, a subject access request should describe which category of information the request relates to, such as newsletter data or contact correspondence, to help the team locate the relevant records efficiently. Where a request is complex or where several requests are received from the same person in a short period, UK GDPR permits the one-month period to be extended by up to two further months, and Grenval will explain any such extension in writing within the first month. Identity checks are proportionate to the sensitivity of the request; a straightforward unsubscribe request typically requires no more than clicking the link in a newsletter email, while an access request for full correspondence history may require confirmation of the email address used to contact Grenval originally.

  • a) Right of access: a copy of personal information held, provided free of charge for a first request.
  • b) Right to erasure: removal of newsletter or correspondence data where there is no lawful reason to keep it.
  • c) Right to object: a reader may object to processing based on legitimate interests, prompting a fresh balancing review.

6. Processors

Grenval may use hosting, email delivery, analytics and security suppliers acting on documented instructions. Suppliers receive only the information needed for their service. Grenval does not sell reader details and does not use health information for advertising audiences. A hosting provider processes server log data and page content solely to keep the website online and secure. An email delivery supplier processes newsletter addresses solely to send requested issues and to manage unsubscribe requests, and does not use that address list for its own marketing purposes. Where a future supplier is added, such as a website analytics tool, it will be added to this section with its name, purpose and any relevant certification, and the cookie policy will be updated to reflect any new storage technology introduced by that supplier before it is activated.

  • a) Hosting and infrastructure supplier: processes technical logs and delivers website content.
  • b) Email delivery supplier: processes newsletter addresses to send issues and manage opt-outs.
  • c) Any future analytics or security supplier will be named here before its technology is activated on the site.

7. International transfers

Some technology suppliers may process information outside the UK. Where this occurs, Grenval seeks an adequacy decision, appropriate contractual safeguards or another lawful transfer mechanism. Details of a supplier can be requested by contacting the address in this policy. A common example is a hosting or email delivery supplier with servers located in the European Economic Area or in a country covered by a UK adequacy regulation, in which case no additional safeguard beyond the adequacy finding is normally required. Where a supplier is based in a country without a UK adequacy decision, Grenval relies on the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses to provide an equivalent level of protection for the information transferred. A reader may ask which transfer mechanism applies to a specific supplier, and Grenval will confirm this in writing within the response times set out in Section 5.

8. Cookies

The site uses a consent cookie named cookieChoice for up to 12 months to remember a visitor’s choice. Session technologies may support basic operation and expire when a browsing session ends. Optional analytics cookies, where enabled, have a maximum lifespan of 13 months and are not placed before the relevant choice. Further detail on each storage technology, including its exact name, purpose and provider, is set out in the separate cookie policy, which this section should be read alongside. No cookie used on grenval.info is used to build a profile of a reader's health interests for advertising purposes, and the website does not currently use third-party advertising cookies. If that changes in a future version of the site, the cookie policy and this section will both be updated before any new technology is activated, and a fresh consent choice will be requested from returning visitors.

9. Children

Grenval is written for adults and is not directed at children. If a parent or guardian believes a child has sent personal information, they may contact [email protected]. The team will assess the request and remove information where there is no lawful reason to retain it. The website does not include age-verification technology, since it is a general informational publication rather than a service targeted at or designed for use by children, and no feature of the site is designed to appeal specifically to a younger audience. Where Grenval becomes aware that a newsletter sign-up or contact message appears to have been submitted by a child, the record will be reviewed promptly and deleted unless a parent or guardian confirms in writing that they wish it to be retained for a specific, lawful reason.

10. Security

Grenval uses access controls, HTTPS where available and limited administrative permissions. No internet transmission is completely secure, so readers should avoid sending sensitive personal details through a general contact form. Suspected security issues can be reported promptly to [email protected]. Administrative access to the website's back end is limited to a small number of authorised individuals, each of whom uses a unique login rather than a shared credential, and access is reviewed periodically to confirm it remains necessary. In the unlikely event of a personal data breach that poses a risk to a reader's rights and freedoms, Grenval will assess the incident in line with UK GDPR Articles 33 and 34 and, where required, will notify the Information Commissioner's Office within 72 hours of becoming aware of the breach and will inform affected readers directly where the risk to them is high.

11. Complaints

Questions should first be sent to Grenval Health Ltd, 51 George Street, Edinburgh EH2 2AF. A person may also complain to the Information Commissioner’s Office at ico.org.uk. Grenval will cooperate with a fair review and keep a record of the steps taken. A reader is encouraged to raise a concern with Grenval directly in the first instance, using either the postal address above or [email protected], so that the team has an opportunity to resolve the matter without the need for external involvement. Grenval aims to acknowledge a complaint within five working days and to provide a substantive response within one month, in line with the response times described in Section 5. If a reader remains unsatisfied after Grenval's response, or prefers to raise the matter independently, the Information Commissioner's Office can be contacted by post at Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, or by telephone on 0303 123 1113.

12. Changes

This policy may change when the site, law or suppliers change. The current version is dated 24 September 2026. Earlier versions can be requested for a reasonable period where available. Material changes will be signposted on the website. A material change is one that affects what information is collected, why it is used, how long it is kept or who it is shared with, and such a change will be flagged with a visible notice on the homepage for a reasonable period following publication. A minor change, such as a correction to a contact detail or a formatting update, may be made without a separate notice but will still update the date shown at the top of this section. Where practicable, Grenval will maintain a short internal change log noting the date and nature of each revision, a copy of which can be requested using the contact details in Section 11.